VS Code port forwarding vs a public preview link
VS Code forwards a port in two clicks, but private ports need your GitHub login and public ones show a warning page. Its limits, and when a link is better.
By Mads Sauer, who makes ouicu, one of the tools here, so read it as a maker's comparison: each fact about another product links to that product's own page, read on . Published .
VS Code forwards a port in two clicks, and that is often all you need. A private port opens only for you, after you sign in with your own GitHub account, which makes it a fine way to check the site on your own phone. A public port opens for anyone, after a dev tunnels warning page. Neither has a password a client can type, which is where a preview link fits.
At a glance
As of , from each product's own pages (listed under Sources). Prices in US dollars.
| Paid from | Free plan | Warning page on free | Passwords and sign-in | |
|---|---|---|---|---|
| VS Code port forwarding | No price listed; it comes with VS Code | Limits on bandwidth and on active machines, which may change | Yes: the dev tunnels anti-phishing page, on a browser's first visit | Private: your own GitHub account only. Public: anyone with the link |
| Microsoft dev tunnels | No price listed; in public preview, without an SLA | 5 GB a month, 10 tunnels, up to 20 MB/s | “When connecting to a web-forwarding url for the first time, users are presented with an interstitial anti-phishing page.” | Private by default; or anyone, your Entra tenant or a GitHub organization |
| ouicu | Hobby, $4 a month | 1 share at a time, 2 hours each, 1 GB a month | Yes, a notice on page loads, once a week per browser and share; none on Hobby and Pro | Password on Hobby and Pro; invited emails on Pro |
How it works
Built into VS Code through Microsoft dev tunnels, with no extension to install. Open the Ports view, choose Forward a Port and type the port. Forwarding a port asks you to sign in with GitHub first, and VS Code shows a Forwarded Address you can copy. Behind it, by default, hosting and connecting both need the same GitHub or Microsoft account.
Private ports: only you
A new forwarded port is private. Opening its address means:
“you'll be required to sign in with the same GitHub account you used to start the port forwarding process”
So a private port suits your own devices: sign in to GitHub once in the phone's browser and you can test there. The guides to testing on an iPhone and on Android have other ways that need no sign-in. A client or a colleague can't open a private port at all, because it wants your account, not theirs.
Public ports: anyone, after a warning page
To let others in, right-click the port, then Port Visibility > Public. Public ports need no sign-in, and VS Code warns:
“If you've opened a Public port, any user with your link can access the forwarded service. Avoid hosting confidential information or insecure services on public ports.”
Visitors also meet the warning page that every dev tunnels web address has: “When connecting to a web-forwarding url for the first time, users are presented with an interstitial anti-phishing page.” Code gets past it: it isn't shown to requests other than GET, or without text/html in Accept, and an X-Tunnel-Skip-AntiPhishing-Page header skips it. A client clicking the link sees it in each new browser.
ouicu Free shows a notice too, once a week per browser and share, on page loads only. Hobby and Pro show none, and instead of “public or only me” you get a password, with Hobby and Pro, or a list of invited email addresses, with Pro.
Dev tunnels' limits
Port forwarding runs on Microsoft dev tunnels, and VS Code's docs say there are limits on bandwidth and on active machines, which may change. The dev tunnels limits are:
- 5 GB a month, 10 tunnels, up to 20 MB/s. The limits reset monthly.
- 1,500 HTTP requests a minute per port, and 1,000 connections at once.
- Request bodies of 16 MB at most.
As for the price: no price listed; in public preview, without an SLA. Microsoft is plain about what it is for:
“Dev tunnels is for adhoc testing and development, not for production workloads.”
ouicu's limits come from your plan: 1 GB a month and shares of 2 hours on Free, up to 150 GB on Pro, and at most 50 MB in one response. See Plans and data.
The devtunnel command: more control
The same service has a command line tool with more choices than VS Code's two. Anonymous access takes one flag:
devtunnel host -p 3000 --allow-anonymous“Allowing anonymous access to a dev tunnel means anyone on the internet is able to connect to your local server, if they can guess the dev tunnel ID.”
- Who gets in: private by default; or anyone, your Entra tenant or a GitHub organization. Access for a GitHub organization needs the Dev Tunnels GitHub app installed in it.
- Without anonymous access, a browser's first request goes to a login page, so a visitor needs a Microsoft or GitHub account you allowed.
- Access tokens for one tunnel, which expire after 24 hours, go in an
X-Tunnel-Authorizationheader: handy for scripts, not for a client. - A tunnel you create keeps its address: “Keep the same dev tunnel url for as long as you need.” A tunnel expires after anything from 1 hour to 30 days, as you set it.
Remote machines and blocked networks
Working over Remote SSH or in a container? The docs say:
“Port forwarding currently exposes only locally-running services.”
And at work, it may not be there at all: an organization can turn it off by blocking global.rel.tunnels.api.visualstudio.com. ouicu only connects out, to ouicu.com and tunnel.ouicu.com, and runs wherever its command line tool does, a remote machine included.
Where VS Code port forwarding is better
- Built into VS Code through Microsoft dev tunnels, with no extension to install.
- By default, hosting and connecting both need the same GitHub or Microsoft account.
The dev tunnels service behind it has more:
- Traffic inspection in the browser's own DevTools.
- Sign-in for your Microsoft Entra tenant or a GitHub organization, which ouicu doesn't have.
To check your own work on your own devices, it costs nothing and is already installed. Use it.
Where ouicu fits better
- A client opens the link with no account: a password with Hobby and Pro, or their email address with Pro.
- An email when someone opens it, with Hobby and Pro, and the last version kept up while your laptop sleeps, with Hobby and Pro.
- A QR code in the terminal for opening it on a phone, and
ouicu deployfor a build that stays up with your laptop off.
Questions people ask
Is VS Code port forwarding free?
No price is listed: it comes with VS Code and runs on dev tunnels, which are in preview, within the limits above.
Why does my forwarded port ask for a GitHub login?
Forwarded ports are private by default and open only for the GitHub account that forwarded them. Right-click the port and set its visibility to Public to let others in.
How do I skip the dev tunnels warning page?
Code can send the X-Tunnel-Skip-AntiPhishing-Page header. A person sees it once in each browser and clicks Continue.
Can I share a forwarded port with a client?
Only as a public port: anyone with the link gets in, after the warning page. For a password or a list of invited people, use a preview link.
Try ouicu
Install it (Getting started), then share the port you were forwarding:
ouicu share 3000Let in only the people you name (Pro):
ouicu share 3000 --name acme --allow anna@acme.comSources
Prices, defaults and quotes about other products, and the day each was last checked at its source.
- Port Forwarding, VS Code docs. Checked .
- Dev tunnels security, Microsoft Learn. Checked .
- What are dev tunnels?, Microsoft Learn. Checked .
- Azure subscription and service limits: dev tunnels, Microsoft Learn. Checked .
- Dev tunnels command-line reference, Microsoft Learn. Checked .